- Home
- Responsible Disclosure
Responsible Disclosure
Last updated: september 2026 (versie 1.0)
EventDock B.V. ("EventDock") supplies camera, connectivity and security systems. The security of our systems and of our clients' data is therefore a high priority.
Have you discovered a vulnerability in our website, our client portal or our services? Please report it to us. We are happy to work with you to resolve the issue quickly and carefully.
This policy supplements our Website Terms & Disclaimer.
This policy applies to:
- www.eventdock.nl and its underlying pages
- The EventDock client portal
- APIs and cloud environments managed by EventDock
- The email and DNS configuration of eventdock.nl
Out of scope:
- Systems, networks and accounts of third parties, including suppliers, hosting providers, camera manufacturers and cloud platforms
- Equipment and networks owned or managed by clients
- Physical locations, poles and on-site installations
- Reports consisting solely of automated scan results without demonstrable impact
- Best-practice advice without a concrete vulnerability, such as missing headers or outdated cipher suites without exploitable risk
During your research, it is not permitted to:
- Access, download, copy, modify or delete other people's data
- Access or share camera footage, personal data or account data of third parties
- Carry out denial-of-service, brute-force, spam or social engineering attacks
- Install malware, backdoors or persistent access
- Force physical access to locations or equipment
- Disrupt the availability or integrity of our systems or those of clients
- Share or publish the vulnerability before it has been resolved and we have agreed on disclosure
Limit your research to the minimum necessary to demonstrate the vulnerability.
Send your report to info@eventdock.nl with the subject "Responsible Disclosure".
Please include:
- A description of the vulnerability and its potential impact
- The URL, endpoint or functionality concerned
- Reproducible steps, with screenshots or logs where relevant
- Your contact details so we can follow up
You may submit your report encrypted or anonymously. If you wish to remain anonymous, we may not always be able to ask you for additional information.
Our contact details are also available in /.well-known/security.txt.
- We confirm receipt of your report within 3 business days.
- Within 14 days of receipt we provide a substantive response, including an assessment of the report and, where possible, an expected resolution timeframe.
- We keep you informed of progress until the vulnerability has been resolved.
- We treat your report confidentially and do not share your personal data with third parties without your consent, unless legally required to do so.
- At your request, we will credit you as the discoverer of the vulnerability once it has been resolved.
If you comply with this policy, we will not take legal action against you in connection with your report and the research reasonably necessary for it.
In that case we regard your actions as a responsible disclosure report and not as an attack on our systems.
This safe harbour does not apply if you breach this policy, misuse or publish data, cause damage, or conduct research on the systems of third parties or of clients. This safe harbour applies to EventDock only and not to third parties.
EventDock does not operate a bug bounty programme and does not offer financial rewards for reports.
We do appreciate your help: on request we will credit you as the discoverer and thank you for your contribution to the security of our systems.
EventDock B.V. Dortherweg 29 7214 PS Epse Chamber of Commerce number: 42095557 Email: info@eventdock.nl Phone: +31 85 505 5059 Website: www.eventdock.nl